CVE-2025-55526

n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py
References
Link Resource
https://github.com/Zie619/n8n-workflows/issues/48 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:n8n:fastapi:0.115.14:*:*:*:*:*:*:*
cpe:2.3:a:n8n:pydantic:2.11.7:*:*:*:*:*:*:*
cpe:2.3:a:n8n:uvicorn:0.35.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-26 14:15

Updated : 2025-09-15 19:38


NVD link : CVE-2025-55526

Mitre link : CVE-2025-55526

CVE.ORG link : CVE-2025-55526


JSON object : View

Products Affected

n8n

  • fastapi
  • uvicorn
  • pydantic

microsoft

  • windows_11
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')